Unrated severityNVD Advisory· Published Oct 7, 2026
CVE-2026-97331
CVE-2026-97331
Description
The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.1.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.